Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.KillFiles.64745

Добавлен в вирусную базу Dr.Web: 2019-11-08

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения
Создает или изменяет следующие файлы
  • %APPDATA%\microsoft\windows\start menu\programs\startup\<Имя файла>.exe
Вредоносные функции
Для затруднения выявления своего присутствия в системе
удаляет теневые копии разделов.
Изменения в файловой системе
Создает следующие файлы
  • C:\far2\documentation\eng\arc_support.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_brazilian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_ukrainian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_turkish.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_thai.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_tchinese.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_swedish.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_spanish.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_schinese.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_russian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_romanian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_portuguese.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_polish.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_norwegian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_koreana.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_korean.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_japanese.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_italian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_hungarian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_greek.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_french.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_german.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_bulgarian.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_czech.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_swedish.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_spanish.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_schinese.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_russian.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_romanian.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_portuguese.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_polish.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_norwegian.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_koreana.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_japanese.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_schinese.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_italian.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_hungarian.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_greek.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_german.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_french.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_finnish.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_english.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_dutch.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_danish.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_finnish.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_english.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_dutch.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_english.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_dutch.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_danish.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_czech.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_bulgarian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_brazilian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_ukrainian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_turkish.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_thai.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_tchinese.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_swedish.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_spanish.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_schinese.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_russian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_romanian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_portuguese.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_polish.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_norwegian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_french.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_german.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_finnish.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_greek.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_danish.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_hungarian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_czech.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_bulgarian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\vgui_brazilian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_ukrainian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_turkish.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_thai.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_tchinese.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_swedish.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_korean.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_tchinese.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_russian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_romanian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_portuguese.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_polish.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_norwegian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_koreana.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_korean.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_japanese.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_italian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\platform_spanish.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_danish_dualtouch.txt.crypted
  • %ProgramFiles(x86)%\winamp\plugins\freeform\xml\about\barcodefont.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_ukrainian.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_english.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_dutch.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_danish.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_czech.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_bulgarian.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_brazilian.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_ukrainian_dualtouch.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_turkish_dualtouch.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_swedish_dualtouch.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_swedish_default.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_spanish_dualtouch.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_spanish_default.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_russian_dualtouch.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_russian_default.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_romanian_dualtouch.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_portuguese_dualtouch.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_portuguese_default.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_polish_dualtouch.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_polish_default.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_norwegian_default.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_norwegian_dualtouch.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_finnish.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_french.txt.crypted
  • %ProgramFiles(x86)%\winamp\whatsnew.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_ukrainian.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_turkish.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_thai.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_tchinese.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_swedish.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_spanish.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_schinese.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_russian.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_portuguese.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_thai.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_polish.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_norwegian.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_koreana.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_korean.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_japanese.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_italian.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_hungarian.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_greek.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_german.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_italian_dualtouch.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_italian_default.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_hungarian_dualtouch.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_polish.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_norwegian.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_koreana.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_korean.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_japanese.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_italian.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_hungarian.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_greek.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_german.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_french.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_finnish.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_english.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_dutch.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_danish.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_czech.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_bulgarian.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_brazilian.txt.crypted
  • %ProgramFiles(x86)%\steam\skins\skins_readme.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_romanian.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_russian.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_portuguese.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_schinese.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_german_dualtouch.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_spanish.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_german_default.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_french_dualtouch.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_french_default.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_finnish_dualtouch.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_finnish_default.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_english_dualtouch.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_english_default.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_dutch_dualtouch.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_koreana.txt.crypted
  • %ProgramFiles(x86)%\steam\servers\serverbrowser_turkish.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_danish_default.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_brazilian_dualtouch.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_brazilian_default.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\fonts\license_cjk.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_ukrainian.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_turkish.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_thai.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_tchinese.txt.crypted
  • %ProgramFiles(x86)%\steam\steam\cached\steamui_postlogon_swedish.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\keyboards\layout_dutch_default.txt.crypted
  • %ProgramFiles(x86)%\steam\tenfoot\resource\localization\tenfoot_romanian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_korean.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_bulgarian.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_french.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_finnish.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_english.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_dutch.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_danish.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_czech.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_bulgarian.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_brazilian.txt.crypted
  • %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\copyright.txt.crypted
  • %ProgramFiles(x86)%\qip 2012\smilies\qip smilies\copyright(eng).txt.crypted
  • %ProgramFiles(x86)%\opera\29.0.1795.47\resources\license.txt.crypted
  • %ProgramFiles(x86)%\mirc\versions.txt.crypted
  • %ProgramFiles(x86)%\mirc\readme.txt.crypted
  • %ProgramFiles(x86)%\microsoft.net\sdk\v1.1\redist.txt.crypted
  • %ProgramFiles(x86)%\microsoft.net\sdk\v1.1\license.txt.crypted
  • %ProgramFiles(x86)%\k-lite codec pack\icaros\icaros license.txt.crypted
  • %ProgramFiles(x86)%\k-lite codec pack\icaros\ffmpeg license.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\supplementaldictionaries\en_us\excluded.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\supplementaldictionaries\en_us\added.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\supplementaldictionaries\en_gb\added.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\supplementaldictionaries\en_gb\excluded.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_german.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_greek.txt.crypted
  • %ProgramFiles(x86)%\steam\logs\connection_log.txt.crypted
  • %ProgramFiles(x86)%\steam\logs\configstore_log.txt.crypted
  • %ProgramFiles(x86)%\steam\logs\bootstrap_log.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_ukrainian.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_turkish.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_thai.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_tchinese.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_swedish.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_spanish.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_russian.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\abbreviations\en_ca\list.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_romanian.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_portuguese.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_polish.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_norwegian.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_koreana.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_korean.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_japanese.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_italian.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_hungarian.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\supplementaldictionaries\en_ca\excluded.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\supplementaldictionaries\en_ca\added.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\dictionaries\en_us\readme_en_us.txt.crypted
  • %ProgramFiles%\java\jre1.8.0_45\thirdpartylicensereadme.txt.crypted
  • %ProgramFiles%\java\jre1.8.0_45\thirdpartylicensereadme-javafx.txt.crypted
  • %ProgramFiles%\java\jre1.8.0_45\readme.txt.crypted
  • C:\far2\plugins\ftp\notes_rus.txt.crypted
  • C:\far2\plugins\ftp\notes.txt.crypted
  • C:\far2\plugins\ftp\ftpcmds_rus.txt.crypted
  • C:\far2\plugins\ftp\ftpcmds.txt.crypted
  • C:\far2\documentation\rus\techinfo.txt.crypted
  • C:\far2\documentation\rus\plugins_review.txt.crypted
  • C:\far2\documentation\rus\plugins_install.txt.crypted
  • C:\far2\documentation\rus\far_faq.txt.crypted
  • C:\far2\documentation\rus\bug_report.txt.crypted
  • C:\far2\documentation\rus\arc_support.txt.crypted
  • C:\far2\documentation\eng\techinfo.txt.crypted
  • C:\far2\documentation\eng\plugins_review.txt.crypted
  • C:\far2\documentation\eng\plugins_install.txt.crypted
  • C:\far2\documentation\eng\far_faq.txt.crypted
  • C:\far2\documentation\eng\bug_report.txt.crypted
  • %ProgramFiles%\java\jre1.8.0_45\lib\jvm.hprof.txt.crypted
  • %ProgramFiles%\winrar\license.txt.crypted
  • %ProgramFiles%\java\jre1.8.0_45\bin\server\xusage.txt.crypted
  • %ProgramFiles%\winrar\rar.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\dictionaries\en_gb\wordnet_license.txt.crypted
  • %ProgramFiles%\winrar\readme.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\dictionaries\en_gb\readme_en_gb.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\dictionaries\en_gb\readme.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\dictionaries\en_gb\license.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\dictionaries\en_gb\changelog.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\dictionaries\en_gb\affdescription.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\dictionaries\en_ca\readme_th_en_ca_v2.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\dictionaries\en_ca\readme_en_ca.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\abbreviations\en_us\list.txt.crypted
  • %ProgramFiles(x86)%\steam\friends\trackerui_schinese.txt.crypted
  • %ProgramFiles(x86)%\steam\logs\content_log.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\adobe\products.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\languagenames2\displaylanguagenames.en_us_posix.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\languagenames2\displaylanguagenames.en_us.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\languagenames2\displaylanguagenames.en_gb_euro.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\languagenames2\displaylanguagenames.en_gb.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\languagenames2\displaylanguagenames.en_ca.txt.crypted
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\typesupport\unicode\mappings\adobe\zdingbat.txt.crypted
  • %ProgramFiles(x86)%\adobe\acrobat reader dc\resource\typesupport\unicode\mappings\adobe\symbol.txt.crypted
  • %ProgramFiles%\winrar\whatsnew.txt.crypted
  • %CommonProgramFiles(x86)%\adobe\reader\dc\linguistics\providers\plugins2\adobehunspellplugin\abbreviations\en_gb\list.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_hungarian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_italian.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_danish.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_postlogon_greek.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_portuguese.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_polish.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_norwegian.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_koreana.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_korean.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_japanese.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_italian.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_hungarian.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_greek.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_german.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_french.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_finnish.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_english.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_dutch.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_danish.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_czech.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_bulgarian.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_brazilian.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_turkish.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_ukrainian.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_romanian.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_russian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_hungarian.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_greek.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_german.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_french.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_finnish.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_english.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_dutch.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_danish.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_czech.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_brazilian.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_brazilian.txt.crypted
  • %ProgramFiles(x86)%\steam\remoteui\static\libs\license.txt.crypted
  • %ProgramFiles(x86)%\steam\public\url_list.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_ukrainian.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_turkish.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_thai.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_tchinese.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_swedish.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_spanish.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamui_schinese.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_thai.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_tchinese.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_swedish.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_spanish.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_schinese.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_russian.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_romanian.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_portuguese.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_polish.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_norwegian.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_koreana.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_korean.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_japanese.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_italian.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_hungarian.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_greek.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_german.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_french.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_finnish.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_english.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_dutch.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_tchinese.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_thai.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_swedish.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_turkish.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_spanish.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_ukrainian.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_schinese.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_russian.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_romanian.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_portuguese.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_polish.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_norwegian.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_korean.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_japanese.txt.crypted
  • %ProgramFiles(x86)%\steam\resource\overlay_japanese.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steambootstrapper_czech.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_greek.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_german.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_french.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_finnish.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_english.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_dutch.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_danish.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_czech.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_brazilian.txt.crypted
  • %ProgramFiles(x86)%\steam\public\steamclean_italian.txt.crypted
  • %WINDIR%\ntbtlog.txt.crypted
Удаляет следующие файлы
  • %WINDIR%\ntbtlog.txt
Самоудаляется.
Другое
Создает и запускает на исполнение
  • '%APPDATA%\microsoft\windows\start menu\programs\startup\<Имя файла>.exe'
  • '%WINDIR%\syswow64\vssadmin.exe' delete shadows /all /quiet' (со скрытым окном)
  • '%WINDIR%\syswow64\cmd.exe' /C choice /C Y /N /D Y /T 3 & Del "<Полный путь к файлу>' (со скрытым окном)
Запускает на исполнение
  • '<SYSTEM32>\vssvc.exe'
  • '%WINDIR%\syswow64\cmd.exe' /C choice /C Y /N /D Y /T 3 & Del "<Полный путь к файлу>
  • '%WINDIR%\syswow64\choice.exe' /C Y /N /D Y /T 3

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке